Filtered by vendor Kordil Edms Project Subscriptions
Filtered by product Kordil Edms Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2013-10066 1 Kordil Edms Project 1 Kordil Edms 2025-08-07 N/A
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw enables remote code execution by uploading a PHP payload and invoking it via a direct HTTP request.
CVE-2020-13888 1 Kordil Edms Project 1 Kordil Edms 2024-11-21 5.4 Medium
Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php.
CVE-2020-13887 1 Kordil Edms Project 1 Kordil Edms 2024-11-21 8.8 High
documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.